Skip to content

v0.2.3 — Enterprise Hardening

Choose a tag to compare

@dahai80 dahai80 released this 27 Aug 02:23
· 38 commits to main since this release
deae2c3

v0.2.3 — Enterprise Hardening Release

This release lands the enterprise audit (audit/fusion-executor-audit-result-0826.md) follow-up: 10 CRITICAL + 15 MAJOR + 12 MINOR fixes, plus ops/observability hardening and glob spec alignment. All 12 GitHub issues closed.

Highlights

v0.2.1 — M-ARCH-1 (architecture)

  • ShellRegistry moved out of Executor to the IPC/PyO3 layer (Arc<ShellRegistry>).
  • Executor regains strict per-task statelessness — expressed in the type system (shell_start takes &registry, 3 fns became associated).
  • Fixes P-PYO3-01: a serve-path Executor rebuild no longer drops background sh-N handles; in-process + serve paths share one registry.

v0.2.2 — Observability & operations

  • M-OPS-01 structured logging: JSON fmt layer teeing a daily-rolling fe.log file with stderr; runtime-reloadable EnvFilter (basis for SIGHUP). Log dir resolves FE_LOG_DIR → ~/.fusion-executor/logs/.
  • M-OPS-02 Prometheus metrics: executor.metrics_prometheus UDS arm returns text format. No HTTP port opened (M-SEC-01). Counters/gauges: fe_exec_total/fe_exec_success/fe_exec_blocked/fe_exec_timeout/fe_exec_failed/fe_rollback_total/fe_rollback_failed/fe_shell_active/fe_connections.
  • M-OPS-06 + m-OPS-03 trace_id: ExecutionRequest/ExecutionResult gain trace_id (auto-gen uuid v4); carried in tracing::span! log context across layers.
  • m-OPS-02 SIGHUP hot-reload: kill -HUP <pid> reloads log level (RUST_LOG) + whitelist extras (FUSION_EXECUTOR_EXTRA_WHITELIST) without restart. SecurityGuard.whitelist → ArcSwap<HashSet> (interior mutability, Executor stays stateless); extras rebuild from baseline, never accumulate; dangerous interpreters rejected.

v0.2.3 — #20 glob E1 spec alignment

  • fe-tools glob(): globset::Glob::new → GlobBuilder::new(pattern).literal_separator(true).build().
  • */? no longer cross / (matches fusion-event E1 ecosystem glob spec); ** still crosses directories.
  • Bug found + fixed by 3 acceptance tests written before the fix (Rule 9): src/*.swift no longer wrongly matches src/sub/a.swift.

Verification

cargo fmt --all -- --check                      # clean
cargo clippy --workspace --all-targets -- -D warnings   # 0 errors
cargo test --workspace                          # 359 passed, 0 failed
pytest python/tests                             # 184 passed, 1 skipped (TCC)
ruff check . && ruff format --check .           # clean
maturin develop --release                       # fusion_executor-0.2.3

Upgrade notes

  • Socket default changed to ~/.fusion-executor/fe.sock (private 0o700 dir, M-SEC-01) — set FUSION_EXECUTOR_SOCK to override.
  • SIGHUP is reload-only (never shuts down); SIGINT/SIGTERM still stop the server.
  • No breaking API changes — trace_id, metrics, logging are all additive.

Full changelog: see CLAUDE.md version blocks (v0.2.1 / v0.2.2 / v0.2.3).